ExamGecko

Salesforce Certified Identity and Access Management Architect Practice Test - Questions Answers, Page 2

List of questions

Question 11

Report
Export
Collapse

Universal Containers (UC) wants to implement SAML SSO for their internal of Salesforce users using a third-party IdP. After some evaluation, UC decides NOT to 65« set up My Domain for their Salesforce org. How does that decision impact their SSO implementation?

IdP-initiated SSO will NOT work.
IdP-initiated SSO will NOT work.
Neither SP- nor IdP-initiated SSO will work.
Neither SP- nor IdP-initiated SSO will work.
Either SP- or IdP-initiated SSO will work.
Either SP- or IdP-initiated SSO will work.
SP-initiated SSO will NOT work
SP-initiated SSO will NOT work
Suggested answer: B
asked 23/09/2024
Kevin Harley
29 questions

Question 12

Report
Export
Collapse

Which two capabilities does My Domain enable in the context of a SAML SSO configuration? Choose 2 answers

App Launcher
App Launcher
Resource deep linking
Resource deep linking
SSO from Salesforce Mobile App
SSO from Salesforce Mobile App
Login Forensics
Login Forensics
Suggested answer: B, C
asked 23/09/2024
Nader Pouri
31 questions

Question 13

Report
Export
Collapse

Universal Containers wants to implement SAML SSO for their internal Salesforce users using a thirdparty IdP. After some evaluation, UC decides not to set up My Domain for their Salesforce org. How does that decision impact their SSO implementation?

SP-initiated SSO will not work.
SP-initiated SSO will not work.
Neither SP- nor IdP-initiated SSO will work.
Neither SP- nor IdP-initiated SSO will work.
Either SP- or IdP-initiated SSO will work.
Either SP- or IdP-initiated SSO will work.
IdP-initiated SSO will not work.
IdP-initiated SSO will not work.
Suggested answer: B
asked 23/09/2024
Yesaldine Salazar
42 questions

Question 14

Report
Export
Collapse

Universal Containers (UC) has a desktop application to collect leads for marketing campaigns. UC wants to extend this application to integrate with Salesforce to create leads. Integration between the desktop application and Salesforce should be seamless. What Authorization flow should the Architect recommend?

JWT Bearer Token Flow
JWT Bearer Token Flow
Web Server Authentication Flow
Web Server Authentication Flow
User Agent Flow
User Agent Flow
Username and Password Flow
Username and Password Flow
Suggested answer: C
asked 23/09/2024
MYKEL PERRY
38 questions

Question 15

Report
Export
Collapse

which three are features of federated Single Sign-on solutions? Choose 3 answers

It federates credentials control to authorized applications.
It federates credentials control to authorized applications.
It establishes trust between Identity store and service provider.
It establishes trust between Identity store and service provider.
It solves all identity and access management problems.
It solves all identity and access management problems.
It improves affiliated applications adoption rates.
It improves affiliated applications adoption rates.
It enables quick and easy provisioning and deactivating of users.
It enables quick and easy provisioning and deactivating of users.
Suggested answer: B, C, E
asked 23/09/2024
Louis Lee
36 questions

Question 16

Report
Export
Collapse

Universal containers (UC) has built a custom based Two-factor Authentication (2fa) system for their existing on-premise applications. Thru are now implementing salesforce and would like to enable a Two-factor login process for it, as well. What is the recommended solution an architect should consider?

Replace the custom 2fa system with salesforce 2fa for on-premise application and salesforce.
Replace the custom 2fa system with salesforce 2fa for on-premise application and salesforce.
Use the custom 2fa system for on-premise applications and native 2fa for salesforce.
Use the custom 2fa system for on-premise applications and native 2fa for salesforce.
Replace the custom 2fa system with an app exchange app that supports on-premise applications and salesforce.
Replace the custom 2fa system with an app exchange app that supports on-premise applications and salesforce.
Use custom login flows to connect to the existing custom 2fa system for use in salesforce.
Use custom login flows to connect to the existing custom 2fa system for use in salesforce.
Suggested answer: D
asked 23/09/2024
Nathalie Yip
38 questions

Question 17

Report
Export
Collapse

Universal containers (UC) has a custom, internal-only, mobile billing application for users who are commonly out of the office. The app is configured as a connected App in salesforce. Due to the nature of this app, UC would like to take the appropriate measures to properly secure access to the app. Which two are recommendations to make the UC? Choose 2 answers

Disallow the use of single Sign-on for any users of the mobile app.
Disallow the use of single Sign-on for any users of the mobile app.
Require high assurance sessions in order to use the connected App
Require high assurance sessions in order to use the connected App
Use Google Authenticator as an additional part of the logical processes.
Use Google Authenticator as an additional part of the logical processes.
Set login IP ranges to the internal network for all of the app users profiles.
Set login IP ranges to the internal network for all of the app users profiles.
Suggested answer: B, C
asked 23/09/2024
Koen Poos
40 questions

Question 18

Report
Export
Collapse

Universal Containers (UC) wants its closed Won opportunities to be synced to a Data warehouse in near real time. UC has implemented Outbound Message to enable near real-time data sync. UC wants to ensure that communication between Salesforce and Target System is secure. What certificate is sent along with the Outbound Message?

The Self-signed Certificates from the Certificate & Key Management menu.
The Self-signed Certificates from the Certificate & Key Management menu.
The default client Certificate from the Develop--> API menu.
The default client Certificate from the Develop--> API menu.
The default client Certificate or the Certificate and Key Management menu.
The default client Certificate or the Certificate and Key Management menu.
The CA-signed Certificate from the Certificate and Key Management Menu.
The CA-signed Certificate from the Certificate and Key Management Menu.
Suggested answer: B
asked 23/09/2024
Kevin Taylor
30 questions

Question 19

Report
Export
Collapse

An architect needs to advise the team that manages the identity provider how to differentiate salesforce from other service providers. What SAML SSO setting in salesforce provides this capability?

Entity id
Entity id
Issuer
Issuer
Identity provider login URL
Identity provider login URL
SAML identity location
SAML identity location
Suggested answer: A
asked 23/09/2024
Adetutu Ogunsowo
45 questions

Question 20

Report
Export
Collapse

The security team at Universal containers(UC) has identified exporting reports as a high-risk action and would like to require users to be logged into salesforce with their active directory (AD) credentials when doing so. For all other uses of Salesforce, Users should be allowed to use AD credentials or salesforce credentials. What solution should be recommended to prevent exporting reports except when logged in using AD credentials while maintaining the ability to view reports when logged in with salesforce credentials?

Use SAML Federated Authentication and Custom SAML jit provisioning to dynamically add or remove a permission set that grants the Export Reports permission.
Use SAML Federated Authentication and Custom SAML jit provisioning to dynamically add or remove a permission set that grants the Export Reports permission.
Use SAML Federated Authentication, treat SAML sessions as high assurance, and raise the session level required for exporting reports.
Use SAML Federated Authentication, treat SAML sessions as high assurance, and raise the session level required for exporting reports.
Use SAML Federated Authentication and block access to reports when accesses through a standard assurance session.
Use SAML Federated Authentication and block access to reports when accesses through a standard assurance session.
Use SAML Federated Authentication with a login flow to dynamically add or remove a permission set that grants the export reports permission.
Use SAML Federated Authentication with a login flow to dynamically add or remove a permission set that grants the export reports permission.
Suggested answer: C
asked 23/09/2024
soufiane chafik
40 questions
Total 248 questions
Go to page: of 25
Search

Related questions